Earlier quoted context omitted.
Apperantly he started the whistleblowing process before any Musk involvement with Twitter. https://twitter.com/KimZetter/status/1562061556745089025
> Apperantly he started the whistleblowing process before any Musk involvement with twitter. According to his lawyer as reported by someone on Twitter. IIRC, lawyers make statements that guilty clients are innocent all the time. If he was working with Musk help him wiggle out of the Twitter deal, it would fatally undermine the goal for to come out publicly about the relationship. I'm skeptical unless they can provide…
Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
231–240 of 645 posts
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#232Earlier quoted context omitted.
Now think about the implications with respect to Twitter DMs that show up in criminal investigations. For instance, consider the Twitter DMs exchanged by Donald Trump, Jr and WikiLeaks. In that particular case, the communication was acknowledged by the party in question, but imagine the two possibilities thousands of employees being able to act on the part of users opens up: 1. Twitter employees could fabricate a cri…
This seems like a huge win for the defense in a case using DMs or Tweets as evidence. It would be quite easy to argue that a highly-politicized org like Twitter _might_ alter tweets or DMs to implicate someone in the opposing party. That’s reasonable doubt that at least some jurors would buy.
But that turns into "there was a sizeable conspiracy to fabricate evidence", as opposed to "a random person out of 2000 got bored, had a grudge, decided to have a laugh, and was acting alone".
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#233I think it's a pretty open secret that Twitter is a fairly broken company. It's no surprise that their security practices are bad, because all their practices are bad. It's also very difficult to view this in isolation when you have the timeline of (1): Fired in January, nothing happens. (2) Musk makes offer for twitter then reneges. (3) Months before the lawsuit gets decided re-emerges with accusations. What happene…
Looking at @paraga's response over the incidence, I don't see attacking Mudge Zatko's character does any help here. Does he know it can backfire? https://twitter.com/donie/status/1562069281545900033
CEO of company defends organization and says previous employee has ulterior motives... Not okay, I hate big tech companies.
See a trend here?
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#234Earlier quoted context omitted.
> Especially since the Whistleblower seems to basically be blowing the whilst on himself. Whistleblowers are by definition insiders.
Sure, but it's not normally the guy in charge of security that gets to complain the security isn't good enough.
1. You find out all the problems. 2. You can't fix all of them (many reasons here, not all malicious) and are setup to take the fall.
Rinse and repeat.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#235Earlier quoted context omitted.
Yes, but that's not the point here. A typical whistleblower would say "There were security problems, and the head of security ignored them." Here, it's "I was the head of security, and security was shitty. I was doing a shitty job, and that's a terrible scandal!"
He tried to change things and was stopped by people actually in power (CEO, the board). Being head of security means nothing if you aren't allowed to do your job. He was also there for less than 2 years. If you read the article, you'll find that Twitter has had awful security practices since at least 2010.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#236Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#237Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…
Twitter Inc. is indeed in very serious trouble if you have someone like Mudge whistleblowing. Now looking at the chaos, damage control and the PR disaster that is happening at Twitter HQ after this, I have zero confidence in whatever Twitter HQ and the CEO is saying other than admitting their total incompetency towards how they handle information security at the company. All attempts to make this disaster disappear w…
There is nothing more evident about the fatal flaws in social media than when news concerning a platform is suppressed on the cited platform.
It highlights the failure of democracy they always purport, and it shows that they really shouldn't display a social "trending" page, because it is subject constantly to the politics and profit making of each platform.
Twitter's trending timeline had long been regarded as an accurate beacon of real life trends, but that really needs to be reevaluated by everyone as the company has regularly displayed "somewhat questionable" behavior in how they manage timelines alone. There is no real way this wouldn't trend somehow on Twitter in my opinion, as it's been on the front page of CNN and many other sites for a long time now.
The security breaches are factual, they have published many incidences of it themselves over years... Their actual reputation for lax security is what works against them most, but it's all on record.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#238Millenials and GenZ may have no idea who Mudge is. I, however, almost lost my first job out of college at a bank because I ran l0phtcrack against our Windows NT 4 server to see if it could crack passwords. I showed my boss, and he pulled me aside into another room and tore my head off for irresponsibly running this tool against a production server. He said I could have been fired if this got out, but he covered my as…
I agree. I grant It’s possible Mudge is A) an old hand and doesn’t know how to run a security program with the tech today B) a strong tech hire who can’t lead a program. But Mudge is still… Mudge, and he’s also proven his ability to collaborate so if he was a bull in a china shop a twitter, that would be surprising. There’s also a broader trend here of well known security leads that originate from that time working a…
I worked with Mudge (not super close, but enough to see how he worked across teams etc) and can certainly say this is not the case. At least when I saw him Mudge was excellent at the program leadership aspect of his role. At one point he ended up a DARPA PM. You can't go from L0pht to DARPA without getting really good at working with other people and leading projects.
While he was always a notable presence, he was also never prone to drama, and very good at having ego when it was important but never letting it get in the way.
Additionally all of the details sound like every KPI chasing consumer facing tech company I've ever worked with. I think we all know a few very competent people who have stood up to leadership at insane tech companies and ultimately gotten fired for it.
Re: Ex-Twitter exec blows the whistle, alleging reckless cybersecurity policies
#239The bots problem is absolutely nightmare issue for a social network. I can't imagine what I'd do if I discovered my network was fake. The whole point of my network is building professional connections and gaining skills for work. Also seeing various weird topics on twitter like kpop or other random things always made me wonder how much artificial bot boosting was done for those who had money to pay the bot net.
Even with FB's automated tools (which are surprisingly good), we still have to "prune" ~10 bot accounts per day.
If we weren't strict about this, in a year 25% of our group would be bot accounts.